zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 12, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics
  • French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
  • Okta Says Data Leaked on Hacking Forum Not From Its Systems

New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics

A new banking trojan called CHAVECLOAK is targeting users in Brazil through phishing emails containing PDF attachments. The phishing emails use DocuSign lures related to contracts to trick users into opening the PDF files, which contain a button to read and sign the documents. However, clicking the button triggers the retrieval of an installer file from a remote link shortened using the Goo.su URL shortening service.

French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers

On March 11, the French government said that a cyberattack of “unprecedented intensity” had targeted several of its services, prompting the activation of a special crisis center to restore online services. A statement from Prime Minister Gabriel Attal’s office further added that the attack had struck multiple ministries. By Monday afternoon, the attack’s impact had been reduced, restoring several impacted services and sites. ZeroFox has observed threat actor group Anonymous Sudan take responsibility for targeting the French government in denial-of-service attacks. The threat actor has particularly named the French Interministerial Directorate of Digital Affairs as its victim.

Okta Says Data Leaked on Hacking Forum Not From Its Systems

Okta denies any involvement in the alleged data leak shared by a threat actor on a hacker forum. According to a spokesperson, the data does not belong to the company and appears to be sourced from public information on the internet. The spokesperson emphasized that the leaked data is not associated with the October 2023 security incident where Okta's support system was breached, leading to the theft of cookies and authentication for some customers. The company conducted an internal investigation in November, revealing that the incident affected all users of the customer support system.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-6606: An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
  • CVE-2023-7192: A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.

BREACHES

Tags: DIB, tlp:green